Blog
/
/
April 22, 2020

AI-Powered Darktrace Email | Defend Against Phishing Attacks

Default blog imageDefault blog imageDefault blog imageDefault blog imageDefault blog imageDefault blog image
22
Apr 2020
Protect your organization from phishing attacks with Antigena Email. Learn how Bunim Murray Productions secures against targeted spear phishing emails.

The 2014 Sony hack changed everything. Bunim/Murray, like other entertainment companies, woke up to the new threats targeting our sector – jumpstarting our journey to improve security.

Bunim/Murray is the production company behind a whole host of reality television shows and is well-known for several hit series such as The Real World (MTV), Road Rules (MTV), The Simple Life (E!), Family or Fiancé (OWN), and Starting Over (syndicated). Bunim/Murray Productions infuses its finely-tuned sense of dramatic story structure to turn the ordinary tales of real people into extraordinary television programming and filmed entertainment. When landing as the CTO at Bunim/Murray, protecting our business was – and still is – a fundamental part of the job. With strong support from the CEO and CFO, I embarked on the journey to bolster cyber defense for our organization.

Bunim/Murray has some unique challenges in security: we onboard and offboard many employees, especially in production. We have a lot of BYOD (‘Bring Your Own Device’) users. Our IT staff is lean, and we don’t want to spend a lot of time and money on security resources or services. Instead, we want to focus on improving business processes – preparing our organization to launch capabilities to remain competitive in an industry undergoing transformation.

So, in searching for security tools, we were looking for technologies with the following criteria:

  • User-friendly
  • Able to continously identify and respond to the latest threats
  • Efficient with IT resources – low on false positives and alerts
  • Cost effective

After being called by Darktrace, I invited the team over to see if it made sense for them to participate in a bake-off with other tools we were assessing. At our meeting, the team at Darktrace spoke to me about the AI and machine learning capabilities, its roots in MI5 cyber operations, how it would fit into our ecosystem, and the product roadmap. Traditionally, I’m not one to be easily impressed by words – so I asked to try it out within our own organization. Within a week, we had the technology installed and up and running in our data center.

Darktrace’s Enterprise Immune System technology immediately began to baseline the dynamic ‘pattern of life’ for our business. It was the first time we had seen all the devices on our network, and we were able to drill down into all of the activity on our environment. But, even more impressive, Darktrace’s AI instantly got to work in the background, alerting us when we needed to investigate an in-progress security event in real time. Not only were we impressed with the machine learning capabilities, we were impressed with the level of support and security expertise Darktrace provided – and continues to provide our business. I canceled the bake-off and bought the system.

As we moved forward on our journey, our highest vulnerability became phishing. We subscribed to a company to train our workforce and got excellent results. We then turned on Microsoft Advanced ATP to help filter spam and phishing emails. And when I learned that Darktrace was pioneering a new approach to neutralize phishing attacks, I got on board early.

Using AI to tackle phishing head on

We were one of the first adopters of Antigena Email, and the first release surprised us. Within days, Antigena Email cut down phishing emails like no other tool I had ever seen before in my career. Using AI, Antigena Email learns all of our users’ activity patterns – how they interact and communicate both internally and externally. It creates a comprehensive and evolving understanding of what’s ‘normal’ for all of our users, and from there, identifies significant anomalies indicative of a vulnerability or threat. Once the threat is detected, Antigena Email contains the attack before it can cause damage.

Incredibly, once we started using Antigena Email, we no longer needed to spend time and money training our users on phishing awareness because we simply weren’t seeing phishing emails anymore – Antigena Email was blocking them before they ever reached the user.

We turned off our Microsoft ATP and instead used Darktrace’s plug-in to Office 365 and the Dropbox monitoring feature. These features turned out to be essential as we increased our remote workforce due to COVID-19.

Antigena Email in action: Neutralizing COVID-19 phishing campaigns

We have all seen the hundreds of thousands of COVID-19-related domains that have been created by cyber-attackers looking to launch novel phishing campaigns. By exploiting the emotional vulnerability of the situation, these attackers craft messages that are so convincing to users that they click on these malicious links. It is our unfortunate reality that threat-actors use these types of events to prey on the collective attention of the population.

As I’m sure countless other organizations have also experienced, Bunim/Murray has not been immune to these types of attacks. In fact, just last week, Antigena Email caught several phishing emails purporting to deliver corporate COVID-19 updates. These emails bore a spoofed Bunim/Murray domain, with the subject line ‘COVID-19 Update 7.4.2020’. Fortunately, due to Antigena Email’s granular analysis of what’s normal for our corporate email communication, it was able to detect this spoofed domain and block the emails from ever reaching any of the target users.

It’s exactly this type of situation that demonstrates the power of Antigena Email. Had these emails reached the user, we might have been in a situation where one of our well-intentioned employees clicked on the malicious link in an attempt to get accurate, up-to-date information – not recognizing that it would introduce malware into our environment. But with Antigena Email, we don’t have to worry about our end user behavior because the AI neutralizes it before it even gets to that point.

Technology that evolves as we do

What threats will be coming after COVID-19? I am not sure. But, I am confident that Darktrace’s AI will be on it. With its ability to ingest new and evolving information from its customer base, coupled with its top-notch security resources, we know that Darktrace will be able to continue to monitor, alert, and respond to new threats – even if those threats have never been seen before.

Inside the SOC
Darktrace cyber analysts are world-class experts in threat intelligence, threat hunting and incident response, and provide 24/7 SOC support to thousands of Darktrace customers around the globe. Inside the SOC is exclusively authored by these experts, providing analysis of cyber incidents and threat trends, based on real-world experience in the field.
Author
Gabe Cortina
CTO, Bunim/Murray Productions

Gabe Cortina is CTO of Bunim/Murray Productions and has over 20 years’ experience in technology leadership roles. Bunim/Murray has been a Darktrace customer since 2017, and uses the Cyber AI Platform to protect their network, email and cloud environments.

Book a 1-1 meeting with one of our experts
Share this article

More in this series

No items found.

Blog

/

Cloud

/

April 2, 2025

Fusing Vulnerability and Threat Data: Enhancing the Depth of Attack Analysis

Default blog imageDefault blog image

Cado Security, recently acquired by Darktrace, is excited to announce a significant enhancement to its data collection capabilities, with the addition of a vulnerability discovery feature for Linux-based cloud resources. According to Darktrace’s Annual Threat Report 2024, the most significant campaigns observed in 2024 involved the ongoing exploitation of significant vulnerabilities in internet-facing systems. Cado’s new vulnerability discovery capability further deepens its ability to provide extensive context to security teams, enabling them to make informed decisions about threats, faster than ever.

Deep context to accelerate understanding and remediation

Context is critical when understanding the circumstances surrounding a threat. It can also take many forms – alert data, telemetry, file content, business context (for example asset criticality, core function of the resource), and risk context, such as open vulnerabilities.

When performing an investigation, it is common practice to understand the risk profile of the resource impacted, specifically determining open vulnerabilities and how they may relate to the threat. For example, if an analyst is triaging an alert related to an internet-facing Webserver running Apache, it would greatly benefit the analyst to understand open vulnerabilities in the Apache version that is running, if any of them are exploitable, whether a fix is available, etc. This dataset also serves as an invaluable source when developing a remediation plan, identifying specific vulnerabilities to be prioritised for patching.

Data acquisition in Cado

Cado is the only platform with the ability to perform full forensic captures as well as utilize instant triage collection methods, which is why fusing host-based artifact data with vulnerability data is such an exciting and compelling development.

The vulnerability discovery feature can be run as part of an acquisition – full or triage – as well as independently using a fast ‘Scan only’ mode.

Figure 1: A fast vulnerability scan being performed on the acquired evidence

Once the acquisition has completed, the user will have access to a ‘Vulnerabilities’ table within their investigation, where they are able to view and filter open vulnerabilities (by Severity, CVE ID, Resource, and other properties), as well as pivot to the full Event Timeline. In the Event Timeline, the user will be able to identify whether there is any malicious, suspicious or other interesting activity surrounding the vulnerable package, given the unified timeline presents a complete chronological dataset of all evidence and context collected.

Figure 2: Vulnerabilities discovered on the acquired evidence
Figure 3: Pivot from the Vulnerabilities table to the Event Timeline provides an in-depth view of file and process data associated with the vulnerable package selected. In this example, Apache2.

Future work

In the coming months, we’ll be releasing initial versions of highly anticipated integrations between Cado and Darktrace, including the ability to ingest Darktrace / CLOUD alerts which will automatically trigger a forensic capture (as well as a vulnerability discovery) of the impacted assets.

To learn more about how Cado and Darktrace will combine forces, request a demo today.

Continue reading
About the author
Paul Bottomley
Director of Product Management, Cado

Blog

/

OT

/

March 28, 2025

Darktrace Recognized as the Only Visionary in the 2025 Gartner® Magic Quadrant™ for CPS Protection Platforms

Default blog imageDefault blog image

We are thrilled to announce that Darktrace has been named the only Visionary in the inaugural Gartner® Magic Quadrant™ for Cyber-Physical Systems (CPS) Protection Platforms. We feel This recognition highlights Darktrace’s AI-driven approach to securing industrial environments, where conventional security solutions struggle to keep pace with increasing cyber threats.

A milestone for CPS security

It's our opinion that the first-ever Gartner Magic Quadrant for CPS Protection Platforms reflects a growing industry shift toward purpose-built security solutions for critical infrastructure. As organizations integrate IT, OT, and cloud-connected systems, the cyber risk landscape continues to expand. Gartner evaluated 17 vendors based on their Ability to Execute and Completeness of Vision, establishing a benchmark for security leaders looking to enhance cyber resilience in industrial environments.

We believe the Gartner recognition of Darktrace as the only Visionary reaffirms the platform’s ability to proactively defend against cyber risks through AI-driven anomaly detection, autonomous response, and risk-based security strategies. With increasingly sophisticated attacks targeting industrial control systems, organizations need a solution that continuously evolves to defend against both known and unknown threats.

AI-driven security for CPS environments

Securing CPS environments requires an approach that adapts to the dynamic nature of industrial operations. Traditional security tools rely on static signatures and predefined rules, leaving gaps in protection against novel and sophisticated threats. Darktrace / OT takes a different approach, leveraging Self-Learning AI to detect and neutralize threats in real time, even in air-gapped or highly regulated environments.

Darktrace / OT continuously analyzes network behaviors to establish a deep understanding of what is “normal” for each industrial environment. This enables it to autonomously identify deviations that signal potential cyber threats, providing early warning and proactive defense before attacks can disrupt operations. Unlike rule-based security models that require constant manual updates, Darktrace / OT improves with the environment, ensuring long-term resilience against emerging cyber risks.

Bridging the IT-OT security gap

A major challenge for organizations protecting CPS environments is the disconnect between IT and OT security. While IT security has traditionally focused on data

protection and compliance, OT security is driven by operational uptime and safety, leading to siloed security programs that leave critical gaps in visibility and response.

Darktrace / OT eliminates these silos by providing unified visibility across IT, OT, and IoT assets, ensuring that security teams have a complete picture of their attack surface. Its AI-driven approach enables cross-domain threat detection, recognizing risks that move laterally between IT and OT environments. By seamlessly integrating with existing security architectures, Darktrace / OT helps organizations close security gaps without disrupting industrial processes.

Proactive OT risk management and resilience

Beyond detection and response, Darktrace / OT strengthens organizations’ ability to manage cyber risk proactively. By mapping vulnerabilities to real-world attack paths, it prioritizes remediation actions based on actual exploitability and business impact, rather than relying on isolated CVE scores. This risk-based approach enables security teams to focus resources where they matter most, reducing overall exposure to cyber threats.

With autonomous threat response capabilities, Darktrace / OT not only identifies risks but also contains them in real time, preventing attackers from escalating intrusions. Whether mitigating ransomware, insider threats, or sophisticated nation-state attacks, Darktrace / OT ensures that industrial environments remain secure, operational, and resilient, no matter how threats evolve.

AI-powered incident response and SOC automation

Security teams are facing an overwhelming volume of alerts, making it difficult to prioritize threats and respond effectively. Darktrace / OT’s Cyber AI Analyst acts as a force multiplier for security teams by automating threat investigation, alert triage, and response actions. By mimicking the workflow of a human SOC analyst, Cyber AI Analyst provides contextual insights that accelerate incident response and reduce the manual workload on security teams.

With 24/7 autonomous monitoring, Darktrace / OT ensures that threats are continuously detected and investigated in real time. Whether facing ransomware, insider threats, or sophisticated nation-state attacks, organizations can rely on AI-driven security to contain threats before they disrupt operations.

Trusted by customers: Darktrace / OT recognized in Gartner Peer Insights

Source: Gartner Peer Insights (Oct 28th)

Beyond our recognition in the Gartner Magic Quadrant, we feel Darktrace / OT is one of the highest-rated CPS security solutions on Gartner Peer Insights, reflecting strong customer trust and validation. With a 4.9/5 overall rating and the highest "Willingness to Recommend" score among CPS vendors, organizations across critical infrastructure and industrial sectors recognize the impact of our AI-driven security approach. Source: Gartner Peer Insights (Oct 28th)

This strong customer endorsement underscores why leading enterprises trust Darktrace / OT to secure their CPS environments today and in the future.

Redefining the future of CPS security

It's our view that Darktrace’s recognition as the only Visionary in the Gartner Magic Quadrant for CPS Protection Platforms validates its leadership in next-generation industrial security. As cyber threats targeting critical infrastructure continue to rise, organizations must adopt AI-driven security solutions that can adapt, respond, and mitigate risks in real time.

We believe this recognition reinforces our commitment to innovation and our mission to secure the world’s most essential systems. This recognition reinforces our commitment to innovation and our mission to secure the world’s most essential systems.

® Download the full Gartner Magic Quadrant for CPS Protection Platforms

® Request a demo to see Darktrace OT in action.

Gartner, Magic Quadrant for CPS Protection Platforms , Katell Thielemann, Wam Voster, Ruggero Contu 12 February 2025

Gartner does not endorse any vendor, product or service depicted in its research publications and does not advise technology users to select only those vendors with the highest ratings or other designation. Gartner research publications consist of the opinions of Gartner’s research organization and should not be construed as statements of fact. Gartner disclaims all warranties, expressed or implied, with respect to this research, including any warranties of merchantability or fitness for a particular purpose.

GARTNER is a registered trademark and service mark of Gartner and Magic Quadrant and Peer Insights are a registered trademark, of Gartner, Inc. and/or its affiliates in the U.S. and internationally and are used herein with permission. All rights reserved. Gartner Peer Insights content consists of the opinions of individual end users based on their own experiences with the vendors listed on the platform, should not be construed as statements of fact, nor do they represent the views of Gartner or its affiliates. Gartner does not endorse any vendor, product or service depicted in this content nor makes any warranties, expressed or implied, with respect to this content, about its accuracy or completeness, including any warranties of merchantability or fitness for a particular purpose.

Continue reading
About the author
Pallavi Singh
Product Marketing Manager, OT Security & Compliance
Your data. Our AI.
Elevate your network security with Darktrace AI